Nathan Alan

PRIVACY POLICY

Effective Date: April 13, 2026 (Last updated: April 13, 2026)

Albar Imports Inc., doing business as Nathan Alan Jewelers (“Nathan Alan Jewelers,” “we,” “us,” or “our”), respects your privacy. This Privacy Policy explains how we collect, use, disclose, and protect your personal information when you visit https://www.nathanalanjewelers.com (the “Website”), use any mobile application we may offer, or otherwise interact with our Services (collectively, the “Services”).

This Policy applies to California residents as required by the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), and related CPPA regulations. We update this Policy at least annually; material changes will be posted with a new effective date. This Policy is available in a printable format and is designed to be accessible (following generally recognized standards such as WCAG 2.1).

1. Information We Collect

In the preceding 12 months, we have collected the following categories of personal information (using the specific categories defined in Civil Code § 1798.140(v) and (ae)). We describe them in a way that provides meaningful understanding of the information involved.

Category of Personal Information

Examples / Description

Collected?

Sources

Specific Business or Commercial Purposes for Collection/Use

Identifiers

Name, email address, phone number, IP address, account name or unique online identifier, device identifiers

Yes

Directly from you (e.g., account creation, checkout, contact forms); automatically from your device/browser; service providers (e.g., analytics)

Fulfilling orders and transactions; providing customer service and account management; communicating with you; fraud prevention and security; improving Services and analytics

California Customer Records (Civ. Code § 1798.140(v)(1)(B))

Name, signature (if applicable), contact information, financial information such as credit/debit card details and purchase history

Yes

Directly from you (orders and payments)

Processing and fulfilling purchases; billing and payment processing; order confirmation and shipping

Commercial Information (Civ. Code § 1798.140(v)(1)(D))

Records of products or services purchased, obtained, or considered; purchase history and preferences

Yes

Directly from you (purchases and browsing)

Fulfilling orders; personalizing recommendations (where consented); marketing our jewelry products and services; business analytics

Internet or Other Electronic Network Activity Information (Civ. Code § 1798.140(v)(1)(F))

Browsing history on our Website, search history, interactions with our ads or pages, clickstream data, cookies and similar tracking

Yes

Automatically via cookies, pixels, web beacons, and similar technologies on our Website

Enabling Website functionality and security; analyzing site performance and user behavior; improving user experience; limited advertising and analytics (subject to opt-out rights)

Geolocation Data (Civ. Code § 1798.140(v)(1)(I))

Imprecise location data derived from IP address (city or region level; we do not collect precise geolocation within a ~1,850-foot radius)

Yes (limited)

Automatically from your device/browser

Fraud prevention; estimating shipping options; site analytics and performance

Inferences Drawn from Personal Information (Civ. Code § 1798.140(v)(1)(K))

Preferences, characteristics, or profiles drawn from the above data (e.g., jewelry style preferences)

Yes (limited)

Derived internally from other collected data

Personalizing product recommendations and improving Services

We do not collect the following categories in the ordinary course of business: protected characteristics (e.g., race, religion), biometric information, audio/visual/sensory data (beyond standard site functionality like images you upload), professional or employment-related information, education information, or precise geolocation. We also do not knowingly collect personal information from children under 16.

Sensitive Personal Information (Civ. Code § 1798.140(ae)): We do not collect or process sensitive personal information beyond what is reasonably necessary and proportionate to provide the Services (e.g., we may process payment card details with required credentials solely for transaction completion). We do not use sensitive personal information for purposes other than those permitted without additional consent (e.g., no use for targeted advertising or profiling that produces significant effects). If we ever do, we will provide a prominent “Limit the Use of My Sensitive Personal Information” link and honor requests accordingly. Imprecise IP-based geolocation is not treated as sensitive precise geolocation.

Retention: We retain each category only as long as reasonably necessary for the disclosed purposes or as required by law. Examples of criteria/periods:

  • Purchase and financial data: Duration of transaction + up to 7 years for tax, accounting, and legal compliance.
  • Account and contact information: Duration of account/activity + 2–5 years after inactivity (or longer if required for disputes).
  • Internet/network activity and inferences: Up to 12–24 months for analytics, unless you opt out or request deletion.
  • We delete or de-identify data when no longer needed, subject to legal holds.

2. How We Use Your Information

We use personal information for the specific business or commercial purposes listed in the table above, including:

  • Fulfilling orders, payments, and shipping.
  • Providing customer service and support.
  • Improving and personalizing our Services.
  • Analytics, fraud prevention, and security.
  • Marketing (with consent where required by law).

We do not use personal information for purposes materially different from those disclosed without providing notice and obtaining any required consent.

3. Sharing and Disclosure of Personal Information

No Sale for Monetary Consideration: We do not sell personal information (as defined under CCPA/CPRA) in exchange for monetary consideration. We have not sold personal information in the preceding 12 months.

Sharing for Cross-Context Behavioral Advertising: We do not share personal information for cross-context behavioral advertising or targeted advertising unless you have affirmatively opted in or we provide the required opt-out. We have not shared for such purposes in the preceding 12 months.

Disclosures for Business Purposes: In the preceding 12 months, we have disclosed the following categories of personal information to service providers and contractors under written contracts that prohibit them from using or disclosing the information except as necessary to perform services for us or as permitted by law.

Category Disclosed

Categories of Recipients (Service Providers/Contractors)

Business Purposes for Disclosure

Identifiers, Customer Records, Commercial Information

Payment processors, shipping carriers, customer service platforms, order fulfillment vendors

Order processing, payment handling, shipping, and customer support

Internet/Network Activity, Inferences

Analytics providers (e.g., Google Analytics), website hosting and performance tools

Site analytics, performance monitoring, and Service improvement

Geolocation Data (imprecise)

Analytics and fraud prevention providers

Fraud detection and basic location-based analytics

We may also disclose personal information to comply with law, in response to legal process, to protect rights/safety, or in connection with a business transfer (e.g., merger). We have no actual knowledge that we sell or share the personal information of consumers under 16 years of age.

4. Cookies and Tracking Technologies

We use necessary cookies for Website functionality, analytics cookies for performance, and similar technologies. You can manage preferences through your browser settings. We honor Global Privacy Control (GPC) signals. When we process a GPC or opt-out signal, we will provide visible confirmation. We do not use these technologies to intercept the content of your electronic communications.

5. California Resident Rights (CCPA/CPRA)

If you are a California resident, you have the following rights (subject to verification and legal exceptions):

  • Right to Know: Request the categories, specific pieces, sources, purposes, and recipients of your personal information collected in the preceding 12 months. If we retain your information longer than 12 months, you may also request data going back to January 1, 2022.
  • Right to Delete: Request deletion of your personal information (with exceptions, e.g., for legal compliance or ongoing transactions).
  • Right to Correct: Request correction of inaccurate personal information (we will also inform relevant third parties where required).
  • Right to Opt-Out of Sale/Sharing: Request to opt-out of any future sale or sharing (including for cross-context behavioral advertising). We provide a “Do Not Sell or Share My Personal Information” link on our website footer.
  • Right to Limit Use of Sensitive Personal Information (if applicable).
  • Right to Non-Discrimination: We will not discriminate against you for exercising any rights.
  • Right to Appeal: If we deny a request (in whole or part), you may appeal the decision.

How to Exercise Your Rights
Submit requests by email to [email protected], by phone at (714) 545-8337, or via our contact form. We verify identity using information already on file (e.g., email + order details or other matching data). We respond within 45 calendar days (extendable once by another 45 days with notice). Authorized agents may submit requests with proper verification.

We honor Global Privacy Control browser signals as valid opt-out requests for sale/sharing and display confirmation when processed.

Do Not Sell or Share My Personal Information
https://www.nathanalanjewelers.com/do-not-share

6. Notice at Collection

At or before the point we collect personal information (e.g., checkout, contact forms, or account creation), we provide a short notice listing the categories collected, purposes, retention information (or criteria), whether sold/shared (no), and links to this Policy and opt-out mechanisms. This full Policy serves as the comprehensive disclosure.

7. Automated Decision-Making Technology (ADMT)

We do not currently use ADMT in a way that makes or meaningfully contributes to significant decisions about you that produce legal or similarly significant effects (e.g., denial of services). If we do in the future, we will provide pre-use notice, opt-out rights (where required), and access to information about the ADMT as mandated by regulations (phased requirements begin 2027 for certain uses).

8. Data Security

We implement reasonable administrative, technical, and physical safeguards. However, no method of transmission or storage is 100% secure.

9. Children’s Privacy

We do not knowingly collect personal information from children under 16. If you are a California resident under 18 and have an account with us, you may request removal of publicly posted content.

10. Shine the Light (Cal. Civ. Code § 1798.83)

California residents may request information about our direct-marketing disclosures once per year. Contact us using the details below.

11. Updates to This Policy

We may update this Policy. We will notify you of material changes by posting the new version with an updated effective and “last updated” date.

12. Contact Us

Albar Imports Inc. d/b/a Nathan Alan Jewelers
23 Corporate Plaza Drive, Suite 150
Newport Beach, CA 92660
Email: [email protected]
Phone: (714) 545-8337

Questions? Contact us at the details above for any concerns about this Policy or our practices.